Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$77,592▲ 1.70%ETH$2,485▲ 2.06%SOL$105.66▲ 6.27%TOTAL CRYPTO$2.67T▼ 0.67%S&P 5007,637.76▼ 1.39%NASDAQ26,418.30▼ 0.85%DOW51,778.04▼ 3.15%GOLD4,424.90▲ 0.10%WTI100.95▲ 18.85%BRENT103.57▲ 13.79%EUR/USD1.1485▼ 0.85%USD/JPY157.08▼ 1.42%DXY100.31▲ 0.66%
Crypto

Revolut Hackers Demand $3M in Monero for 680 Accounts’ Data

The group behind the Revolut breach wants 6,000 XMR within 24 hours and threatens to sell passports, licenses and crypto transaction records of 680 customers.

Pexels – Marta Branco

Hackers who stole customer data from Revolut are demanding $3 million in Monero and have set a 24-hour deadline before they sell the records to criminal groups, according to the Financial Times. The group, calling itself “iamnotavillain”, published the ultimatum on a website with a countdown clock, asking for 6,000 XMR, worth about $3 million at current prices. The deadline expires on Thursday, September 17.

The breach affected around 680 customers, and the attackers appear to have picked their targets with care. Blockchain analysis was reportedly used to single out people with significant crypto holdings across Switzerland, France and other European countries. The stolen files include passports, driving licenses, home addresses, bank details and cryptocurrency transaction histories. A 60-second screen recording provided to the Financial Times showed the documents and banking records in full.

How the data was taken

The attackers did not break into Revolut’s systems. Instead, they impersonated government officials and used fraudulent legal information requests to trick the company into handing over customer records. This method, sometimes called a fraudulent government request attack, requires no exploit at all, only convincing paperwork and a compliance team under pressure to respond quickly to what looks like an official demand.

Revolut said it has since blocked the domain used in the deception and formally alerted law enforcement. The company also said its core infrastructure and primary databases saw no unauthorized access, framing the incident as a data disclosure failure rather than a hack of its platforms.

Revolut confirmed it has not received any direct ransom demand from the group, which creates an odd gap between the group’s public countdown and the company’s official position. The UK Information Commissioner’s Office has opened a formal investigation into the incident, and UK and EU regulators have scheduled supervisory hearings on the matter before the end of the third quarter.

Why Monero

The choice of Monero is not accidental. The privacy coin uses cryptographic techniques that obscure sender, receiver and amount, making payments far harder to trace than bitcoin or ether. Major exchanges including Binance, Coinbase and Kraken have delisted XMR over the years under regulatory pressure, but it remains the standard request in ransom demands for exactly this reason. Once converted, the funds are difficult for investigators to follow without specialized analysis firms, and even then attribution is uncertain.

The demand also highlights a risk specific to crypto customers. The stolen transaction records can link visible on-chain wealth to real identities, turning KYC files into a targeting list. A person whose passport and wallet history sit in the same stolen file is exposed in ways a plain banking customer is not. Security researchers have warned for years that exchange and fintech KYC databases are, in effect, maps of who holds what, and this breach shows what happens when that map leaks.

Context for the fintech

The timing is awkward for Revolut, which recently received conditional approval to form a national bank in the US. The company has built much of its growth on crypto trading for retail users, and the breach shows how the KYC data that regulation requires becomes a liability when it leaks. The same documents collected to satisfy anti-money-laundering rules are now sitting in an extortionist’s hands.

Social engineering against compliance teams has become a recurring attack path for crypto-adjacent firms. The attacker needs no exploit, only a convincing letterhead and a name. Firms in the sector have been moving toward callback verification and multi-channel confirmation of legal requests, but the practice is far from uniform, and smaller compliance teams remain the weak point.

The ICO investigation is expected to examine whether Revolut’s verification of the requests met data protection standards, and whether the disclosure of 680 customers’ records could have been prevented with tighter procedures. Under UK data protection law, the regulator can levy fines calculated as a percentage of global turnover for serious failures, though any penalty would come after the investigation concludes, likely well into next year.

For the affected customers, the practical risk goes beyond identity theft. Transaction histories combined with identity documents allow targeted phishing, physical security threats against people known to hold crypto, and what security firms call wrench attacks, where thieves assume the victim can unlock a wallet under duress. Several of the affected customers are believed to hold six-figure crypto positions, according to the reporting.

A familiar pattern for the industry

The case resembles earlier breaches at crypto firms where compliance records, rather than wallets, were the target. Custodial platforms hold exactly the data attackers want: verified identities linked to holdings. As regulated crypto grows, the volume of such data grows with it, and so does its value on criminal markets.

Neither Revolut nor law enforcement has said whether any payment will be considered, and the company’s public statements have focused on the absence of a direct demand rather than the group’s published countdown. The UK’s National Crime Agency has not commented publicly on the case. Whether the group follows through on its threat to sell the data will likely become clear within days of the deadline passing.

For now, the episode stands as a reminder that the weakest link in crypto security is often not the chain itself but the paperwork around it. A forged letter cost 680 customers their privacy, and the attackers want their $3 million in the one currency built never to be traced.

SourcesFinancial Times; Reuters; CoinDesk; UK Information Commissioner’s Office statements
Share: X